Junglewise Threat Intelligence

CVE-2026-79300: SEP sesam user authorization bypass with MFA in Active Directory

CVE-2026-79300 · Severity: low · CVSS 3.5 · Published 2026-09-12

Executive brief

SEP sesam is a backup and recovery software that integrates with Active Directory for user authentication and multi-factor authentication (MFA) to secure access. A vulnerability in versions before 5.2.0.24 allows attackers to register multiple OTP authenticators for the same user account by exploiting case-sensitivity differences between SEP sesam and Active Directory, effectively bypassing MFA protections.

Technical details

The vulnerability stems from inconsistent username case-sensitivity handling between SEP sesam and Active Directory. Active Directory treats usernames as case-insensitive, but SEP sesam distinguishes between different letter casing (e.g., "user", "User", "USER" are treated as separate accounts in SEP sesam). When AD authentication and MFA are both enforced, an attacker can create multiple SEP sesam user accounts for the same AD account using different capitalization variants, allowing registration of additional OTP Authenticator devices that bypass the intended MFA enforcement. This is a logic flaw in the user authorization and account mapping mechanism. The vulnerability affects SEP sesam versions before 5.2.0.24 and requires AD authentication and MFA to be configured; patch is available in version 5.2.0.24 or later.

Affected products

  • SEP sesam before 5.2.0.24

Timeline

  • 2026-09-12: disclosed
  • 2026-09-12: patched: Fixed in version 5.2.0.24 Artemis V6

References